Multi-modal adaptive attack test method and system for automatic driving model
Through the multimodal adaptive attack testing method and system, the problems of insufficient data diversity and attack algorithm flexibility in the autonomous driving model testing platform are solved, and comprehensive, automated and efficient testing of the autonomous driving model is achieved, thereby improving the security and robustness of the model.
Patent Information
- Application Number
- CN202511009483.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-22
- Publication Date
- 2025-09-16
AI Technical Summary
Existing autonomous driving model testing platforms have deficiencies in data diversity, attack algorithm flexibility, and testing efficiency, and are unable to comprehensively evaluate the performance of the model in complex and dynamic environments. Existing methods also make it difficult to significantly reduce the segmentation performance of the model after the backdoor is triggered, making it impossible to fully evaluate the security of the model.
A multimodal adaptive attack testing method and system is adopted, and the model to be tested is adapted through automated parsing technology to generate diverse test scenarios. The test is executed using a distributed computing architecture, and the test results are monitored and analyzed in real time. The multimodal attack algorithm library and reinforcement learning module are integrated to dynamically optimize attack parameters and generate vulnerability analysis and optimization suggestions.
It enables comprehensive, automated, and efficient testing of autonomous driving models, improves the security and robustness of the models, supports user-defined models and data sets, covers complex environments and attack scenarios, and provides real-time visualization and structured reports.
Smart Images

Figure CN120652820A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of autonomous driving technology, and in particular to a multimodal adaptive attack testing method and system for an autonomous driving model. Background Art
[0002] With the rapid development of artificial intelligence technologies like deep learning and the application of various high-precision sensors, autonomous driving technology has made significant progress in recent years. In particular, with the booming intelligent electric vehicle market, advanced autonomous driving systems such as Tesla's Autopilot, Google's Waymo, Baidu's Apollo, and Huawei's ADS2.0 are driving innovation and development in the industry. Countries around the world, particularly major automobile producing countries like the United States, China, and Germany, have enacted legislation to regulate and promote the research and development and application of autonomous driving technology, hoping that these intelligent systems will improve traffic safety, optimize traffic flow, and even transform the way people travel.
[0003] However, autonomous driving systems have also been involved in numerous traffic accidents during actual operation. For example, according to a report by the U.S. National Highway Traffic Safety Administration, between January 1 and October 16, 2023, Level 2 autonomous vehicles were involved in 386 traffic accidents, sparking widespread public concern about the safety of autonomous driving. Therefore, to ensure the safety and reliability of autonomous driving systems, extensive and thorough testing is essential before system deployment. Traditional autonomous driving model testing methods primarily rely on static test datasets and manually configured attack algorithms. These methods generally cannot fully evaluate model performance in real-world environments, especially when facing unknown attacks or sudden environmental changes.
[0004] Most existing autonomous driving algorithm testing platforms focus on providing fixed datasets and attack algorithm combinations. While these platforms can provide initial model validation, they often fail to meet user needs for diverse datasets and attack scenarios. For example, some existing platforms may only support a single dataset type (such as an image dataset for a specific traffic scenario) and a limited number of attack methods, resulting in poor generalization of test results and an inability to effectively evaluate model performance in complex and dynamic environments. Furthermore, many existing platforms do not support users uploading customized algorithm models for testing, which limits user flexibility in actual use and prevents them from performing personalized testing of the model based on their needs.
[0005] Current autonomous driving model testing platforms typically include the following technical solutions:
[0006] Static dataset testing: Most autonomous driving test platforms provide a fixed set of datasets, including common traffic scene datasets and image datasets. Users select these datasets to test uploaded autonomous driving algorithm models. These platforms typically use public datasets (such as KITTI and Cityscapes), which cover a variety of urban traffic scenarios. However, these static datasets have limitations when simulating real-world driving environments. In particular, they fail to fully cover diverse factors such as weather conditions, traffic density, and geographical environments, resulting in poor generalization of test results.
[0007] Attack Algorithm Testing: To verify the robustness of autonomous driving algorithms, existing test platforms have introduced a variety of attack algorithms (such as adversarial attacks and fuzz testing). Adversarial attacks are a common attack method in autonomous driving systems. They test the system's performance in harsh environments by making small perturbations to input images or sensor data. Related research has shown that adversarial sample attacks can effectively evaluate the performance of autonomous driving algorithms under abnormal inputs. However, most platforms only provide a fixed combination of attack algorithms, lack flexible customization support, and are unable to cope with complex and changing attack scenarios.
[0008] Custom model upload and testing: Some platforms allow users to upload customized autonomous driving models and select appropriate test datasets and attack algorithms for verification. However, these platforms often lack compatibility support for user-uploaded models, and their testing frameworks and test combinations are inflexible, making it impossible to conduct personalized, in-depth testing based on the characteristics of different algorithms and datasets.
[0009] Existing backdoor attack testing methods for semantic segmentation models have the following shortcomings:
[0010] Single victim and target categories: Existing methods usually only perform backdoor attacks on specific categories and cannot effectively test the impact of global category mapping errors.
[0011] Insufficient testing intensity: Existing methods are unable to significantly reduce the segmentation performance of the model after the backdoor is triggered, which limits the impact of the attack and makes it impossible to fully evaluate the security of the model. Summary of the Invention
[0012] The limitations of existing methods significantly restrict their application and verification in real-world scenarios. This paper aims to address the problems of existing autonomous driving model testing methods, such as insufficient data diversity (relying on static datasets and lacking the ability to dynamically simulate complex scenarios), the simplification of attack algorithms, low testing efficiency, and low automation, through an innovative automated testing framework.
[0013] The present invention provides a multi-modal adaptive attack testing method and system for autonomous driving models, which mainly includes:
[0014] Obtain the autonomous driving perception model to be tested uploaded by the user, and adapt the autonomous driving perception model to be tested to the test environment through automated parsing technology; generate diversified test scenarios based on the test data set and attack strategy selected by the user and perform multimodal attack testing on the autonomous driving perception model to be tested; use a distributed computing architecture to execute the multimodal attack test, and dynamically allocate computing resources to process test tasks; monitor the process of the multimodal attack test in real time and analyze the test results, and generate a test report containing vulnerability analysis and optimization suggestions.
[0015] Furthermore, the method of obtaining the autonomous driving perception model to be tested uploaded by the user and adapting the autonomous driving perception model to be tested to the test environment through automated parsing technology includes: receiving the autonomous driving perception model to be tested uploaded by the user, and identifying the framework type of the autonomous driving perception model to be tested; for the framework type, using containerization technology to perform architectural parsing on the autonomous driving perception model to be tested; based on the parsing result, converting the autonomous driving perception model to be tested into a standard format to adapt to the test environment; for the type of the autonomous driving perception model to be tested, generating a corresponding test parameter template and pushing it to the user; and initializing and configuring the autonomous driving perception model to be tested through the test parameter template.
[0016] Furthermore, the method generates diversified test scenarios based on the test data set and attack strategy selected by the user and performs multimodal attack testing on the autonomous driving perception model to be tested, including: obtaining the test data set selected by the user, and generating diversified test scenarios for the test data set using style transfer technology; injecting sensor interference data to simulate abnormal conditions in a real environment based on the diversified test scenarios; constructing a multimodal attack combination based on the attack strategy selected by the user and applying it to the autonomous driving perception model to be tested; testing the autonomous driving perception model to be tested through the multimodal attack combination, and recording performance changes during the test.
[0017] Furthermore, the multimodal attack test is performed using a distributed computing architecture, and computing resources are dynamically allocated to process test tasks, including: decomposing the task of the multimodal attack test into multiple subtasks; using a distributed computing architecture to perform parallel processing on the multiple subtasks; dynamically allocating the computing resources to the multiple subtasks based on the load status of the computing resources; monitoring the execution status of the multiple subtasks, and automatically retrying or migrating abnormal subtasks.
[0018] Furthermore, the real-time monitoring of the multimodal attack test process and analysis of the test results to generate a test report containing vulnerability analysis and optimization suggestions includes: obtaining performance indicator data during the multimodal attack test process, and displaying the changing trend of the performance indicator data in real time; analyzing the response characteristics of the autonomous driving perception model to be tested based on the performance indicator data; locating potential vulnerabilities in the autonomous driving perception model to be tested based on the analysis results; generating corresponding optimization suggestions for the potential vulnerabilities and integrating them into the test report; and outputting the test report to the user in a preset format.
[0019] Furthermore, for the framework type, containerization technology is used to perform architectural analysis on the autonomous driving perception model to be tested, including: obtaining a configuration file of the framework type and loading a corresponding parsing tool; for the configuration file, using the parsing tool to extract structural information of the autonomous driving perception model to be tested; based on the structural information, verifying the compatibility of the autonomous driving perception model to be tested with the test environment; generating a compatibility verification result and feeding it back to the initialization configuration process.
[0020] Furthermore, the attack strategy selected by the user is used to construct a multimodal attack combination and apply it to the autonomous driving perception model to be tested, including: obtaining the attack strategy selected by the user, and determining the attack mode corresponding to the attack strategy; constructing a multimodal attack combination for the attack mode, and adjusting the parameters of the multimodal attack combination; generating attack data for the autonomous driving perception model to be tested based on the adjusted parameters; inputting the attack data into the autonomous driving perception model to be tested, and recording the output results of the autonomous driving perception model to be tested; analyzing the output results, and evaluating the impact of the multimodal attack combination on the autonomous driving perception model to be tested.
[0021] Another object of the present invention is to provide a multimodal adaptive attack testing system for autonomous driving models, comprising:
[0022] The user interaction layer provides a user interface and supports model upload and dataset / attack algorithm selection.
[0023] The data processing and enhancement layer dynamically generates diverse test scenarios based on CycleGAN style migration and supports user-defined style templates;
[0024] The attack strategy and optimization layer integrates a multi-modal attack algorithm library and dynamically optimizes attack parameters through reinforcement learning;
[0025] The test execution layer uses Kubernetes cluster scheduling and Celery task queue to achieve concurrent execution of test plans;
[0026] The analysis and visualization layer displays the attack effects in real time through the TensorBoard / Grafana dashboard;
[0027] The report generation layer automatically generates structured test reports, including vulnerability location, quantitative analysis, and optimization suggestions.
[0028] The technical solution provided by the embodiment of the present invention may have the following beneficial effects:
[0029] The present invention discloses a multimodal attack testing method for an autonomous driving model. The method adapts the model to be tested to the test environment through automated parsing technology, generates diversified test scenarios based on the data set and attack strategy selected by the user, uses a distributed computing architecture to perform multimodal attack testing, monitors the test process in real time, and analyzes the results. The present invention proposes an automated, diversified, and efficient testing solution for the security testing of autonomous driving perception models. The model architecture is parsed through containerization technology, various scenarios are generated through style transfer, a multimodal attack combination is constructed, and computing resources are dynamically allocated to achieve a comprehensive test of the model. At the same time, the present invention can also analyze performance indicators in real time, locate potential vulnerabilities, and provide optimization suggestions, effectively improving the security and robustness of the autonomous driving perception model.
[0030] This invention utilizes intelligent model parsing and cross-platform adaptation technology: based on a lightweight containerized architecture (Docker) and ONNX runtime optimization, it enables automatic parsing and seamless adaptation of multi-framework models (TensorFlow, PyTorch, etc.). Through intelligent identification of model types (classification / detection / segmentation) and parameter template recommendations, it significantly reduces user configuration complexity and improves test compatibility.
[0031] This dynamic dataset enhancement technology, based on style transfer, leverages CycleGAN and domain randomization to dynamically generate diverse scenes (such as rainstorms, haze, and nighttime illumination) from the original dataset (e.g., GTSDB), improving the model's generalization capabilities in unknown environments. Users can also upload custom style templates (e.g., specific city street scenes) to generate targeted test data.
[0032] Multi-process distributed testing engine: Using the Kubernetes containerized architecture and Celery task queue, it enables parallel scheduling of test tasks and elastic resource expansion. It supports the concurrent execution of hundreds of test scenarios, significantly improving efficiency.
[0033] The present invention adopts an adaptive attack strategy based on reinforcement learning: it introduces a deep reinforcement learning (DRL) module (such as the PPO algorithm) to dynamically optimize attack parameters (such as perturbation intensity and attack step size) to maximize the exposure of model vulnerabilities; it supports multimodal attack collaboration (such as image adversarial samples + lidar point cloud interference) to simulate complex adversarial scenarios.
[0034] This invention provides full-link automated analysis and optimization: It builds a model vulnerability library based on the knowledge graph, automatically associates historical test data, and generates optimization suggestions (such as adversarial training parameter configuration). It also integrates SHAP interpretive analysis to visualize the impact of attacks on model decisions. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 This is an architecture diagram of a multimodal adaptive attack testing system for autonomous driving models according to the present invention.
[0036] Figure 2 This is a flowchart of the robustness test sequence in the implementation of the present invention. DETAILED DESCRIPTION
[0037] To further understand the content of the present invention, the present invention is described in detail with reference to the accompanying drawings and examples. The present invention will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are intended only to illustrate the relevant invention and are not intended to limit the invention. It should also be noted that, for ease of description, only portions relevant to the invention are shown in the accompanying drawings.
[0038] This invention is designed for comprehensive robustness testing of autonomous driving perception models. By integrating style transfer data enhancement, adaptive multimodal attack strategies, and distributed concurrent testing techniques, it builds an intelligent, automated testing platform. Users can upload various models and flexibly combine extreme weather datasets (such as rainstorm and haze generation data) with attack algorithms (such as image adversarial samples and lidar deception). The system automatically adapts and executes the test process, visualizing attack effects and model performance indicators in real time and generating in-depth analysis reports. This provides efficient and comprehensive model security assessment and optimization support for automakers and research institutions, covering key scenarios such as extreme environment simulation, malicious attack defense, and multimodal collaborative testing.
[0039] The multimodal adaptive attack testing method and system for autonomous driving models in this embodiment may specifically include:
[0040] S1: Obtain the autonomous driving perception model to be tested uploaded by the user, and adapt the autonomous driving perception model to be tested to the test environment through automated parsing technology.
[0041] S2: Generate diverse test scenarios based on the test data set and attack strategy selected by the user and perform multimodal attack tests on the autonomous driving perception model to be tested.
[0042] S3, using a distributed computing architecture to execute the multimodal attack test, and dynamically allocating computing resources to process the test tasks.
[0043] S4, monitor the process of the multimodal attack test in real time and analyze the test results, and generate a test report including vulnerability analysis and optimization suggestions.
[0044] Specifically, the step of obtaining the autonomous driving perception model to be tested uploaded by the user and adapting the autonomous driving perception model to be tested to the test environment through an automated parsing technology includes: S11, receiving the autonomous driving perception model to be tested uploaded by the user, and identifying a framework type of the autonomous driving perception model to be tested;
[0045] S12. For the framework type, use containerization technology to perform architecture analysis on the autonomous driving perception model to be tested. S13. Based on the analysis results, convert the autonomous driving perception model to be tested into a standard format to adapt to the test environment. S14. For the type of the autonomous driving perception model to be tested, generate a corresponding test parameter template and push it to the user. S15. Initialize and configure the autonomous driving perception model to be tested through the test parameter template.
[0046] The method of generating diversified test scenarios and performing a multimodal attack test on the autonomous driving perception model to be tested based on the test dataset and attack strategy selected by the user includes: S21, obtaining the test dataset selected by the user, and generating diversified test scenarios for the test dataset using a style transfer technique;
[0047] S22. Inject sensor interference data to simulate abnormal conditions in a real environment based on the diversified test scenarios. S23. Construct a multimodal attack combination based on the attack strategy selected by the user and apply it to the autonomous driving perception model to be tested. S24. Test the autonomous driving perception model to be tested using the multimodal attack combination and record performance changes during the test.
[0048] The multimodal attack test is executed using a distributed computing architecture, and computing resources are dynamically allocated to process the test task, including: S31, decomposing the task of the multimodal attack test into multiple subtasks; S32, using a distributed computing architecture to perform parallel processing on the multiple subtasks; S33, dynamically allocating the computing resources to the multiple subtasks according to the load status of the computing resources; S34, monitoring the execution status of the multiple subtasks, and automatically retrying or migrating abnormal subtasks.
[0049] The real-time monitoring of the multimodal attack test process and analysis of the test results to generate a test report containing vulnerability analysis and optimization suggestions includes: S41, obtaining performance indicator data during the multimodal attack test process, and displaying the changing trend of the performance indicator data in real time; S42, analyzing the response characteristics of the autonomous driving perception model to be tested based on the performance indicator data; S43, locating potential vulnerabilities in the autonomous driving perception model to be tested based on the analysis results; S44, generating corresponding optimization suggestions for the potential vulnerabilities and integrating them into the test report; S45, outputting the test report to the user in a preset format.
[0050] The containerization technology is used to perform architecture analysis on the autonomous driving perception model to be tested for the framework type, including: S121, obtaining the configuration file of the framework type and loading the corresponding parsing tool; S122, using the parsing tool to extract the structural information of the autonomous driving perception model to be tested for the configuration file; S123, verifying the compatibility of the autonomous driving perception model to be tested with the test environment based on the structural information; S124, generating a compatibility verification result and feeding it back to the initialization configuration process.
[0051] The method of constructing a multimodal attack combination for the attack strategy selected by the user and applying it to the autonomous driving perception model to be tested includes: S231, obtaining the attack strategy selected by the user, and determining the attack mode corresponding to the attack strategy; S232, constructing a multimodal attack combination for the attack mode, and adjusting the parameters of the multimodal attack combination; S233, generating attack data for the autonomous driving perception model to be tested based on the adjusted parameters; S234, inputting the attack data into the autonomous driving perception model to be tested, and recording the output results of the autonomous driving perception model to be tested; S235, analyzing the output results, and evaluating the impact of the multimodal attack combination on the autonomous driving perception model to be tested.
[0052] refer to Figure 1 An embodiment of the present invention also provides a multimodal adaptive attack testing system for autonomous driving models. The system architecture adopts a layered modular design and is divided into six layers. Each layer has independent functions and works together to ensure the efficiency and intelligence of automated robustness testing.
[0053] Specifically.
[0054] The user interaction layer provides a user interface, supports model uploading (compatible with frameworks such as TensorFlow and PyTorch), and dataset and attack algorithm selection. Leveraging Docker containerization and ONNX runtime optimization, it automatically parses and adapts multiple model types (classification, detection, and segmentation), lowering the barrier to entry for users. Intelligent model type identification (classification, detection, and segmentation) and parameter template recommendations significantly reduce user configuration complexity and improve test compatibility.
[0055] The data processing and enhancement layer dynamically generates diverse test scenarios (such as heavy rain and haze) based on CycleGAN style transfer and supports user-defined style templates (such as specific city street scenes). It injects sensor noise (such as lidar point cloud interference) to simulate hardware failures or abnormal interference in real environments. Using CycleGAN and domain randomization, it dynamically generates diverse scenarios (such as heavy rain, haze, and nighttime illumination) from the original dataset (such as GTSDB), improving the model's generalization ability in unknown environments. It supports users to upload customized style templates (such as specific city street scenes) to generate targeted test data.
[0056] The attack strategy and optimization layer integrates a multimodal attack algorithm library and dynamically optimizes attack parameters through reinforcement learning. It supports multimodal attack collaboration (such as vision + lidar attack) and covers complex adversarial scenarios.
[0057] The test execution layer uses Kubernetes cluster scheduling and Celery task queues to achieve concurrent execution of hundreds of test scenarios. It dynamically allocates computing resources (GPU / CPU) and automatically migrates or retries abnormal tasks, significantly improving testing efficiency.
[0058] The analysis and visualization layer displays attack effects (such as mAP decline trends and adversarial sample comparisons) in real time through TensorBoard / Grafana dashboards. It correlates historical vulnerability data based on the knowledge graph, locates sensitive model modules (such as the SPP layer of YOLOv5), and uses SHAP interpretability analysis to visualize attack decision paths.
[0059] The report generation layer automatically generates structured test reports, including vulnerability location, quantitative analysis, and optimization suggestions (such as adversarial training parameter configuration). It supports one-click export to Word / LaTeX, meeting the needs of academic research and industrial deployment.
[0060] For example, combined Figure 2 This embodiment tests the robustness of the autonomous driving perception model.
[0061] 1) Initialization phase:
[0062] The user uploads a target detection model (YOLOv5) trained with the PyTorch framework. The platform automatically parses the model structure using Docker container technology and converts it into a standardized format using ONNX runtime optimization, compatible with multi-framework testing environments. The system identifies the model type as "target detection" and recommends a traffic scene dataset and adversarial attack algorithm template. The basic dataset GTSDB (traffic sign detection) is selected, and two scenes (1,200 images each) of heavy rain and nighttime illumination are dynamically generated through CycleGAN style transfer to cover extreme environment testing requirements. A multimodal attack combination is selected: image adversarial attack (AutoAttack) and LiDAR spoofing (LiDAR-Spoofing). The PPO reinforcement learning module is used to automatically optimize the attack parameters (perturbation strength ε = 0.1, attack step size = 10).
[0063] The user set the test parameters for each test scenario, with a batch size of 64, a number of attack rounds of 100, and a learning rate of 0.001.
[0064] 2) Testing and analysis phase:
[0065] The system distributes tasks to three GPU nodes through the Kubernetes cluster, dynamically allocating resources and reducing the total test time from eight hours per task to two hours. Task status is monitored in real time, and abnormal tasks are automatically migrated to backup nodes to ensure test continuity. During the test, the changing trends of the benign accuracy and attack accuracy for each two rounds are displayed in real time, and are visually displayed through the echarts diagram on the front end, allowing users to observe the performance changes of the model under different attacks in real time. Based on knowledge graph technology, the system analyzes each layer of the model and locates the SPP layer as a sensitive module, which helps to further understand the weaknesses of the model in specific scenarios and finds that the missed detection rate of "No Entry" signs increases in heavy rain scenarios. The system uses the SHAP (SHapley Additive exPlanations) analysis method to reveal how attacks affect the weight distribution of the model's feature extraction layer, providing specific guidance for model improvement.
[0066] 3) Report generation stage:
[0067] After the test is complete, the system generates a structured report containing content such as benign and attack accuracy, attack effect analysis, vulnerability root causes, and optimization suggestions. To more intuitively display the analysis results, the system uses a variety of visualization techniques, such as charts (bar charts, line charts, pie charts), heat maps, and dashboards, to transform complex data into easy-to-understand graphics. The report can be exported to Word format with one click to meet the needs of industrial deployment. When previewing the Word report template, users can intuitively see the final report effect, and support secondary editing after export.
[0068] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that the technical solutions described in the above embodiments can still be modified, or some of the technical features thereof can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A multi-modal adaptive attack testing method and system for autonomous driving models, characterized by: include: Obtain the autonomous driving perception model to be tested uploaded by the user, and adapt the autonomous driving perception model to the test environment through automated parsing technology; Generate diverse test scenarios based on the test dataset and attack strategy selected by the user and perform multimodal attack tests on the autonomous driving perception model to be tested; Using a distributed computing architecture to perform the multimodal attack test and dynamically allocate computing resources to process the test tasks; Monitor the process of the multimodal attack test in real time and analyze the test results to generate a test report containing vulnerability analysis and optimization suggestions.
2. The multimodal adaptive attack testing method according to claim 1, wherein: The step of obtaining the autonomous driving perception model to be tested uploaded by the user and adapting the autonomous driving perception model to be tested to the test environment through automated parsing technology includes: receiving the autonomous driving perception model to be tested uploaded by a user, and identifying the framework type of the autonomous driving perception model to be tested; Based on the framework type, containerization technology is used to perform architecture analysis on the autonomous driving perception model to be tested; According to the analysis results, the autonomous driving perception model to be tested is converted into a standard format to adapt to the test environment; Generate a corresponding test parameter template for the type of autonomous driving perception model to be tested and push it to the user; The autonomous driving perception model to be tested is initialized and configured using the test parameter template.
3. The multimodal adaptive attack testing method according to claim 1, wherein: The method generates diversified test scenarios based on the test data set and attack strategy selected by the user and performs multimodal attack tests on the autonomous driving perception model to be tested, including: Obtain a test dataset selected by the user, and use style transfer technology to generate diverse test scenarios for the test dataset; Injecting sensor interference data according to the diverse test scenarios to simulate abnormal conditions in a real environment; Based on the attack strategy selected by the user, a multimodal attack combination is constructed and applied to the autonomous driving perception model to be tested; The autonomous driving perception model to be tested is tested using the multimodal attack combination, and performance changes during the test are recorded.
4. The multimodal adaptive attack testing method according to claim 1, wherein: The multimodal attack test is performed using a distributed computing architecture, and computing resources are dynamically allocated to process the test task, including: Decomposing the multimodal attack test task into multiple subtasks; For the multiple subtasks, a distributed computing architecture is used to perform parallel processing; Dynamically allocating the computing resources to the plurality of subtasks according to a load status of the computing resources; Monitor the execution status of the multiple subtasks and automatically retry or migrate abnormal subtasks.
5. The multimodal adaptive attack testing method according to claim 1, wherein: The real-time monitoring of the multimodal attack test process and analysis of the test results to generate a test report containing vulnerability analysis and optimization suggestions includes: Obtaining performance indicator data during the multimodal attack test and displaying the changing trend of the performance indicator data in real time; Analyzing the response characteristics of the autonomous driving perception model to be tested based on the performance indicator data; Based on the analysis results, locate potential vulnerabilities in the autonomous driving perception model to be tested; Generate corresponding optimization suggestions for the potential vulnerabilities and integrate them into the test report; The test report is output to the user in a preset format.
6. The multimodal adaptive attack testing method according to claim 2, wherein: For the framework type, the containerization technology is used to perform architecture analysis on the autonomous driving perception model to be tested, including: Obtain the configuration file of the framework type and load the corresponding parsing tool; For the configuration file, using the parsing tool to extract structural information of the autonomous driving perception model to be tested; Verifying the compatibility of the autonomous driving perception model to be tested with the test environment based on the structural information; Generate compatibility verification results and feed them back into the initial configuration process.
7. The multimodal adaptive attack testing method according to claim 3, wherein: The attack strategy selected by the user is used to construct a multimodal attack combination and apply it to the autonomous driving perception model to be tested, including: Obtaining the attack strategy selected by the user and determining the attack mode corresponding to the attack strategy; Constructing a multimodal attack combination according to the attack mode, and adjusting parameters of the multimodal attack combination; generating attack data targeting the autonomous driving perception model to be tested according to the adjusted parameters; Inputting the attack data into the autonomous driving perception model to be tested, and recording the output result of the autonomous driving perception model to be tested; Analyze the output results and evaluate the impact of the multimodal attack combination on the autonomous driving perception model to be tested.
8. A multimodal adaptive attack testing system for an autonomous driving model using the method according to any one of claims 1 to 7, characterized in that: include: The user interaction layer provides a user interface and supports model upload and dataset / attack algorithm selection. The data processing and enhancement layer dynamically generates diverse test scenarios based on CycleGAN style migration and supports user-defined style templates; The attack strategy and optimization layer integrates a multi-modal attack algorithm library and dynamically optimizes attack parameters through reinforcement learning; The test execution layer uses Kubernetes cluster scheduling and Celery task queue to achieve concurrent execution of test plans; The analysis and visualization layer displays the attack effects in real time through the TensorBoard / Grafana dashboard; The report generation layer automatically generates structured test reports, including vulnerability location, quantitative analysis, and optimization suggestions.
Citation Information
Cited By
Automatic safety test scheme generation method and system for intelligent networked automobile, and medium
CN122284579A